4.3 SDN Data Plane 79
(data path) and the high-level routing decisions (control path) colocate
on the same device. An OpenFlow-enabled switch separates these
two functions. The data path portion still resides in the switch, but
high-level routing decisions are moved to a flow controller, typically
a standard server. The OpenFlow switch and controller communicate
via the OpenFlow protocol, which defines operation and management
(OAM) messages.
Figure 4.7 shows the basic component in the initial OpenFlow
design. Later OpenFlow has evolved to other more complex structures such as multiple tables. The match field can match any packet
headers, for example, Ethernet address, IP headers, or MPLS header
fields. The typical actions can be forward, modify, and drop. Each
entry is associated with a counter for collecting statistics purposes.
Similar to routing or access control rules, each rule has a priority.
When multiple rules match the same packet, the one with higher
priority is selected. Finally, each rule has an expiration time. This is
for preventing outdated rules. Once the time out is reached, the rule
is removed by the switch.
With OpenFlow rules, each packet matches a specified header, the
counters are updated, and the appropriate actions taken. If a packet
matches multiple flow entries, the entry with the highest priority is
chosen. An entry’s header fields can contain wildcard values, meaning
that it can match any value in the corresponding position. It is a
TCAM-like match to flows. The basic set of OpenFlow actions are
L4
dport
L4
sport
IP
Prot
When to delete the entry
# of packet/bytes processed by the rule
What order to process the rule
IP
ToS
Time out
Priority
Counter
Action
Match
IP
Dst
IP
Src
Eth
type
MAC
dst
MAC
src
VLAN
pcp
VLAN
ID
1. Forward packet to zero or more ports
2. Encapsulate and forward to controller
3. Send to normal processing pipeline
4. Modify fields
Switch
Port
Figure 4.7 OpenFlow overview.
Précédent

- 99/195

Suivant